[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2013:085 -- Mandriva groff

ID: oval:org.secpod.oval:def:1300179Date: (C)2013-04-17   (M)2023-11-09
Class: PATCHFamily: unix




Multiple vulnerabilities has been found and corrected in groff: contrib/pdfmark/pdfroff.sh in GNU troff before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file . The gendef.sh, doc/fixinfo.sh, and contrib/gdiffmk/tests/runtests.in scripts in GNU troff 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack on a gro#####.tmp or /tmp/##### temporary file . The contrib/eqn2graph/eqn2graph.sh, contrib/grap2graph/grap2graph.sh, and contrib/pic2graph/pic2graph.sh scripts in GNU troff 1.21 and earlier do not properly handle certain failed attempts to create temporary directories, which might allow local users to overwrite arbitrary files via a symlink attack on a file in a temporary directory, a different vulnerability than CVE-2004-1296 . The updated packages have been patched to correct these issues.

Platform:
Mandriva Enterprise Server 5.2
Product:
groff
Reference:
MDVSA-2013:085
CVE-2009-5044
CVE-2009-5079
CVE-2004-1296
CVE-2009-5080
CVE    4
CVE-2009-5080
CVE-2009-5079
CVE-2004-1296
CVE-2009-5044
...
CPE    1
cpe:/o:mandriva:enterprise_server:5.2

© SecPod Technologies